{"data":{"id":"d45ec49e-ebcd-47f0-9e3f-fda8f04ba1e6","title":"DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval","summary":"DeepSeek Harness, an open-source tool for running AI coding agents in a sandbox (an isolated environment where programs can only access certain files), had a critical flaw that let an agent disable its own sandbox protections with a single command. An attacker could trick the agent into calling the tool's web interface to switch to a 'danger-full-access' mode, allowing the agent to write files outside its workspace without approval, though the fix was deployed on August 27.","solution":"Install version 0.1.2-alpha.2 or later from npm. The CVE record names 0.1.2-alpha.1 as fixed (released August 27), but the first fixed release published to npm is 0.1.2-alpha.2 (August 30). The current npm release, 0.1.2-rc.1 (September 3), also carries the fix. If you cannot upgrade, stop the web interface when not in use and remove any tunnel, proxy, or port forward that reaches it.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html","publishedAt":"2026-09-09T11:17:07.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["jailbreak"],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["DeepSeek","DeepSeek Harness"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-09T11:17:07.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}